
CVE-2026-41336 OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, enabling loading of attacker-controlled hook co… https://www.cve.org/CVERecord?id=CVE-2026-41336
Post summary
The tweet announces a newly disclosed vulnerability in OpenClaw that permits environment variable override to load attacker‐controlled hooks.
